The average cost of a serious cyber incident has doubled in five years. Regulators now expect boards to understand the risk and to show they are ready to respond.
Questions every board should ask
- What are our five most critical systems and how fast can we restore them?
- When did we last rehearse a major incident?
- Who decides whether to pay a ransom?
- How do we know our suppliers are secure?
Resilient companies treat cyber as an operational risk, run regular exercises with the leadership team and invest in recovery as much as in prevention.



